Techniques for security algorithm selection in handover from evolved packet system to 5g system

By ensuring the use of 256-bit cryptographic algorithms during handovers from EPS to 5GS, the technology addresses the inconsistency in algorithm support, enhancing security and maintaining consistent security standards across networks.

WO2025156438A1PCT designated stage Publication Date: 2025-07-31ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/086316
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-04-07
Publication Date
2025-07-31

AI Technical Summary

Technical Problem

The inconsistency in cryptographic algorithm support between Evolved Packet System (EPS) and 5G System (5GS) poses challenges during handover, leading to potential security weaknesses due to the use of 128-bit algorithms instead of the more secure 256-bit algorithms supported by 5GS.

Method used

Implement mechanisms to ensure that 256-bit cryptographic algorithms are used for both Non-Access-Stratum (NAS) and Access-Stratum (AS) security during handover or registration procedures from EPS to 5GS, by requesting and selecting appropriate security algorithms based on the user equipment's capabilities.

Benefits of technology

Ensures the use of stronger 256-bit cryptographic algorithms, enhancing security during handovers and registrations, thereby preventing potential security breaches and maintaining consistent security standards across networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024086316_31072025_PF_FP_ABST
    Figure CN2024086316_31072025_PF_FP_ABST
Patent Text Reader

Abstract

A method of wireless communication is provided. The method comprises: receiving, by a mobile management entity (MME) in a first network from a base station in the first network, a first message indicating an initiation of a handover operation for a user device from the first network to a second network; receiving, by the MME from an access and mobility management function (AMF) in the second network, a second message requesting security capability information of the user device for the second network; sending, by the MME to the user device, a third message requesting the security capability information of the user device for the second network; receiving, by the MME from the user device, a response message including the security capability information of the user device for the second network; and sending, by the MME to the AMF, the security capability information of the user device for the second network.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNIQUES FOR SECURITY ALGORITHM SELECTION IN HANDOVER FROM EVOLVED PACKET SYSTEM TO 5G SYSTEMTECHNICAL FIELDThis document relates to systems, devices and techniques for wireless communications.BACKGROUNDWireless communication technologies are moving the world toward an increasingly connected and networked society. The rapid growth of wireless communications and advances in technology has led to greater demand for capacity and connectivity. Other aspects, such as energy consumption, device cost, spectral efficiency, and latency are also important to meeting the needs of various communication scenarios. In comparison with the existing wireless networks, next generation systems and wireless communication techniques need to provide support for an increased number of users and devices, as well as support an increasingly mobile society.SUMMARYVarious methods and apparatus for configuring channel state information reference signals for tracking in wireless communications are provided.In one example aspect, a method of wireless communication is disclosed. The method comprises: receiving, by a mobile management entity (MME) in a first network from a base station in the first network, a first message indicating an initiation of a handover operation for a user device from the first network to a second network; receiving, by the MME from an access and mobility management function (AMF) in the second network, a second message requesting security capability information of the user device for the second network; sending, by the MME to the user device, a third message requesting the security capability information of the user device for the second network; receiving, by the MME from the user device, a response message including the security capability information of the user device for the second network; and sending, by the MME to the AMF, the security capability information of the user device for the second network.In another example aspect, a method of wireless communication is disclosed. The method comprises: receiving, by an access and mobility management function (AMF) from a mobile management entity (MME) in a first network, a request for relocating a user device from the first network to a second network; sending, by the AMF to the MME, a message requesting security capability information of the user device for the second network; and receiving, by the AMF from the MME, the security capability information of the user device for the second network.In another example aspect, a method of wireless communication is disclosed. The method comprises receiving, by a user device from a mobile management entity (MME) in a first network, a message requesting security capability information of the user device for a second network; and sending, by the user device to the MME, a response message including the security capability information of the user device for the second network.In another example aspect, a method of wireless communication is disclosed. The method comprises receiving, by an access and mobility management function (AMF) in a second network from a mobile management entity (MME) in a first network, a first message requesting for relocating a user device from the first network to the second network, the first message including a first security context for the first network; generating, by the AMF, a second security context for the second network corresponding to the first security context for the first network, the second security context being generated with or without selecting a security algorithm for the second network based on whether the first message including a security capability information of the user device for the second network; and sending, by the AMF to a gNB in the second network, a second message requesting a handover and including a selected security algorithm or security parameters calculated based on candidate algorithms.In another example aspect, a method of wireless communication is disclosed. The method comprises receiving, by a user device from a network node in a first network, a handover command to perform a handover from the first network to a second network, the handover command including security parameters; checking whether the handover command includes a security algorithm selected for the second network or a candidate security algorithm for the second network, the security algorithm being configured to protect signaling messages; comparing, in response to the checking indicates that the handover command includes the candidate security algorithm for the second network algorithms, the candidate security algorithm with security capability information of the user device; and selecting a 256-bit algorithm to be used for the second network based on a result of the comparing that indicates the 256-bit algorithm is supported by the user device and an access and mobility management function (AMF) .In another example aspect, a method of wireless communication is disclosed. The method comprises receiving, by a network node in a second network from an access and mobility management function (AMF) in a first network, a handover request from the first network to the second network, the handover request including 1) security capability information of a user device for the second network in a case that the security capability information of the user device has been provided to the AMF from a mobile management entity (MME) or 2) a container including MACs calculated with different keys derived from different candidate algorithms included in an algorithm list for the user device in a case that the security capability information has not been provided to the AMF from the MME; and receiving, by the network node from the user device, a handover complete message.In another example aspect, a method of wireless communication is disclosed. The method comprises receiving, by an AMF from a user device, a registration request including security capability information of the user device, the registration request received after completing a handover from a first network to a second network; comparing the security capability information of the user device with security capabilities in a current security context; updating the current security context with the security capability information included in the registration request in a case that a result of the comparing indicates that the security capability information is different from the security capabilities in the current security context; and selecting a security algorithm for protecting signaling messages.In another example aspect, a method of wireless communication is disclosed. The method comprises sending, by a user device to an AMF, a registration request including security capability information of the user device, the registration request sent after completing a handover from a first network to a second network; performing a first SMC procedure that activates a first security context updated by the AMF based on the security capability information included in the registration request; and performing a second SMC procedure that activates a second security context updated by a network node in the second network based on the security capability information included in the registration request.In another example aspect, a method of wireless communication is disclosed. The method comprises receiving, by a network node in a second network from a user device, a registration request including security capability information of the user device, the registration request received after completing a handover from a first network to the second network; comparing the security capability information of the user device with security capabilities in a current security context; updating the current security context with the security capability information included in the registration request in a case that a result of the comparing indicates that the security capability information is different from the security capabilities in the current security context; and selecting a security algorithm for protecting signaling messages.In yet another example aspect, a wireless communications apparatus comprising a processor is disclosed. The processor is configured to implement methods described herein.In another example aspect, the various techniques described herein may be embodied as processor-executable code and stored on a computer-readable program medium.The details of one or more implementations are set forth in the accompanying drawings, and the description below. Other features will be apparent from the description and drawings, and from the claims.BRIEF DESCRIPTION OF THE DRAWINGSFIG. 1 illustrates a handover from an EPS to 5GS over N26.FIGS. 2 and 3 illustrate examples of a handover process from EPS to 5GS based on some implementations of the disclosed technology.FIG. 4 illustrates an example of a registration process performed after a handover from EPS to 5GS based on some implementations of the disclosed technology.FIG. 5 shows an example wireless communications network based on some implementations of the disclosed technology.FIG. 6 is a block diagram of an example of a wireless communication apparatus based on some implementations of the disclosed technology.FIGS. 7-15 are example flowcharts of a wireless communication method based on some implementations of the disclosed technology.DETAILED DESCRIPTIONThe disclosed technology provides implementations and examples for security algorithm selection techniques in a handover from an evolved packet system to 5G system.In order to deal with the potential threats of halving security strength posed by quantum computing, the 5G system (5GS) is considered to introduce support for 256-bit symmetric algorithms. However, no matter what algorithms 5GS supports, the Evolved Packet System (EPS) will only support 128-bit cryptographic algorithms. The inconsistent length of supporting cryptographic algorithms may cause problems in EPS and 5GS interworking scenarios.According to the relevant specification (e.g., 3GPP TS 33.501 clause 8.4) , during the handover from EPS to 5GS over N26, if the target AMF does not receive the UE 5G security capabilities from the source MME, the target AMF shall assume that a default set of 5G security algorithms are supported by the UE, from which the NAS and AS security algorithms are selected by the AMF and gNB. Since the default set of 5G security algorithms only includes ciphering algorithms NEA0, 128-NEA1 and 128-NEA2, and integrity algorithm 128-NIA1 and 128-NIA2, for UE and 5GS supporting 256-bit cryptographic algorithms, they can only agree on using 128-bit cryptographic algorithm for NAS and AS security during handover procedure. If the re-selection of algorithm does not take place in the registration procedure following handover from EPS to 5GS, the 128-bit cryptographic algorithm will be continually used for data confidentiality and integrity protection, leading to a weaker protection strength.The various implementations of the disclosed technology propose a mechanism enabling UE and 5GS to agree on using 256-bit cryptographic algorithms for NAS (Non-Access-stratum) and AS (Access-stratum) security during handover or registration procedure after mobility from EPS to 5GS. While the implementations are discussed for the handover from EPS to 5GS, the disclosed technology can be applied to different networks without being limited to EPS and 5GS.FIG. 1 illustrates a handover from an EPS to 5GS over N26, which is described in the relevant specification. The description below is based on clause 4.11.1.2.2 in TS 23.502 and only includes steps and description that are relevant to security.As the UE is connected to the EPS, the source MME has a current EPS security context for the UE. The current EPS security context may be a mapped EPS security context resulting from a previous mobility from 5GC, or a native EPS security context resulting from a primary authentication with the EPS.1. The source eNB sends a Handover Required message to the source MME, including UE's identity.NOTE: The source MME checks whether the UE's security capabilities and access rights are valid in order to decide whether it can initiate handover to 5GS.2. The source MME selects the target AMF and sends a Forward Relocation Request to the selected target AMF. The source MME includes UE's EPS security context including KASME, eKSI, UE EPS security capabilities, selected EPS NAS algorithm identifiers, uplink and downlink EPS NAS COUNTs, {NH, NCC} pair, in this message. If the source MME has the UE NR security capabilities stored, then it will forward the UE NR security capabilities as well to the target AMF.3. The target AMF shall construct a mapped 5G security context from the EPS security context received from the source MME. The target AMF shall derive a mapped KAMF'key from the received KASME and the NH value in the EPS security context received from the source MME as described in clause 8.6.2.If the target AMF receives the UE 5G security capabilities, then the target AMF shall select the 5G NAS security algorithms (to be used in the target AMF for encryption and integrity protection) which have the highest priority from its configured list.If the target AMF does not receive the UE 5G security capabilities from the source MME, then the target AMF shall assume that the following default set of 5G security algorithms are supported by the UE (and shall set the UE 5G security capabilities in the mapped 5G NAS security context according to this default set) :a. NEA0, 128-NEA1 and 128-NEA2 for NAS signalling ciphering, RRC signalling ciphering and UP ciphering;b. 128-NIA1 and 128-NIA2 for NAS signalling integrity protection, RRC signalling integrity protection and UP integrity protection.The target AMF then derives the complete mapped 5G security context. The target AMF shall derive the 5G NAS keys (i.e., KNASenc and KNASint) from the new KAMF'with the selected 5G NAS security algorithm identifiers as input, to be used in AMF as described in clause A. 8. The uplink and downlink 5G NAS COUNTs associated with the derived 5G NAS keys are set to the value as described in clause 8.6.2. The ngKSI for the newly derived KAMF'key is defined such as the value is taken from the eKSI of the KASME key (i.e. included in the received EPS security context) and the type is set to indicate a mapped security context. The target AMF shall store the EPS NAS security algorithms received from the source MME in the mapped 5G security context. Similar to N2-Handover defined in Clause 6.9.2.3.3, the target AMF shall also set the NCC to zero and shall further derive the temporary KgNB using the mapped KAMF'key and the uplink NAS COUNT value of 232-1 as specified in Annex A. 9.The target AMF associates this mapped 5G Security context with ngKSI.NOTE: The target AMF derives a temporary KgNB using the mapped KAMF'instead of using the {NH, NCC} pair received from the MME. The uplink NAS COUNT value for the initial KgNB derivation is set to 232-1. The reason for choosing such a value is to avoid any possibility that the value may be used to derive the same KgNB again.The target AMF shall create a NAS Container to signal the necessary security parameters to the UE. The NAS Container shall include a NAS MAC, the selected 5G NAS security algorithms, the ngKSI associated with the derived KAMF'a nd the NCC value associated with the NH parameter used in the derivation of the KAMF'. The target AMF shall calculate the NAS MAC as described in clause 6.9.2.3.3. with the COUNT parameter set to the maximal value of 232-1.The target AMF shall increment the downlink NAS COUNT by one after creating a NAS Container.4. The target AMF requests the target gNB / ng-eNB to establish the bearer (s) by sending the Handover Request message.The target AMF sends the NAS Container created in step 3 along with, the {NCC=0, NH=derived temporary KgNB} , the New Security Context Indicator (NSCI) , and the UE security capabilities in the Handover Request message to the target gNB / ng-eNB. The target AMF shall further set the NCC to one and shall further compute a NH as specified in Annex A. 10. The target AMF shall further store the {NCC=1, NH} pair.5. The target gNB / ng-eNB shall selects the 5G AS security algorithms from the list in the UE security capabilitiesThe target gNB / ng-eNB shall compute the KgNB to be used with the UE by performing the key derivation defined in Annex A. 11 with the {NCC, NH} pair received in the Handover Request message and the target PCI and its frequency ARFCN-DL. The target gNB / ng-eNB shall associate the NCC value received from AMF with the KgNB. The target gNB  / ng-eNB shall then derive the 5G AS security context, by deriving the 5G AS keys (KRRCint, KRRCenc, KUPint, and KUPenc) from the KgNB and the selected 5G AS security algorithm identifiers as described in Annex A. 8 for gNB and in Annex A. 7 in TS 33.401

[0010] .The target gNB / ng-eNB sends a Handover Request Ack message to the target AMF. Included in the Handover Request Ack message is the Target to Source Container, which contains the selected 5G AS algorithms, the keySetChangeIndicator, the NCC value from the received {NH, NCC} pair, and the NAS Container received from the target AMF. If the target gNB / ng-eNB had received the NSCI, it shall set the keySetChangeIndicator field to true, otherwise it shall set the keySetChangeIndicator field to false.6. The target AMF sends the Forward Relocation Response message to the source MME. The required security parameters obtained from gNB / ng-eNB in step 5 as the Target to Source Container are forwarded to the source MME.7. The source MME sends the Handover Command to the source eNB. The source eNB commands the UE to handover to the target 5G network by sending the Handover Command. This message includes all the security related parameters in the NAS Container obtained from the target AMF in step 6.8. The UE derives a mapped KAMF'key from the KASME in the same way the AMF did in step 3. It shall also derive the 5G NAS keys and KgNB corresponding to the AMF and the target gNB / ng-eNB in step 3 and step 5. The UE shall further set the selected EPS NAS security algorithms in the 5G security context to the NAS security algorithms used with the source MME. It associates this mapped 5G security context with the ngKSI included in the NAS Container. The UE shall verify the NAS MAC in the NAS Container.If verification of the NAS MAC fails, the UE shall abort the handover procedure. Furthermore, the UE shall discard the new NAS security context if it was derived and continue to use the existing NAS and AS security contexts.NOTE: Void.The mapped 5G security context shall become the current 5G security context.9. The UE sends the Handover Complete message to the target gNB / ng-eNB. This shall be ciphered and integrity protected by the AS keys in the current 5G security context.10. The target gNB / ng-eNB notifies the target AMF with a Handover Notify message.If the UE has a native 5G security context established during the previous visit to 5GS, then the UE shall provide the associated the 5G GUTI as an additional GUTI in the Registration Request following the handover procedure. The UE shall use the mapped 5G security context to protect the subsequent Registration Request message over 3GPP access. The target AMF shall validate the integrity of the Registration Request message using the mapped security context. Upon successful validation, the target AMF shall send a context request message to the old AMF and shall include the additional GUTI and an indication that the UE is validated. Upon receiving the context request message with the indication that the UE is validated, the old AMF shall skip the integrity check and transfer the native 5G security context to the target AMF. The AMF shall retrieve the native security context using the 5G GUTI. If the AMF determines to activate the native security context, the AMF shall perform a NAS SMC procedure.NOTE: It is up to AMF when to activate the native 5G security context.If the handover is not completed successfully, the new mapped 5G security context cannot be used in the future. In this case, the AMF shall delete the new mapped 5G security context.If the AMF has no native 5G security context available when the UE performs the Registration Request (protected by the mapped 5G security context) following the handover procedure, then the AMF via the SEAF should run a primary authentication depending on local operator policy.The handling of security contexts in the case of multiple active NAS connections in the same PLMN's serving network is given in clasue 6.4.2.2.The description below is provided based on 3GPP TS 33.501 clause 8.2, which discusses registration procedure for mobility from EPS to 5GS over N26.During mobility from EPS to 5GS, the security handling described below shall apply.When the UE performs idle mode mobility from EPS to 5GS, and if the UE has a native non-current 5G context, then the UE shall make the native non-current 5G context as the current one. The UE shall discard any mapped 5G security context.The UE shall include the UE 5G security capability alongside the mapped 5G GUTI in the Registration Request message. The UE shall also include the 5G GUTI and the ngKSI that identify a current 5G security context if available, e.g. established during an earlier visit to 5G, and integrity protect the Registration Request using the selected security algorithms in the current 5G NAS security context as it is performed for a 5G NAS message over a 3GPP access. If the UE has no current 5G security context then the UE shall send the Registration Request message without integrity protection. As per clause 5.5.1.2.2 in 3GPP 24.501, the Registration Request shall contain the TAU request or ATTACH request integrity protected using the EPS NAS security context shared with the source MME as it is performed for a LTE NAS message, then the UE shall increment its stored uplink EPS NAS COUNT value by one.NOTE: The enclosed TAU request or ATTACH request in the Registration Request contains a complete TAU Request or ATTACH request.Upon receipt of the Registration Request, the AMF shall interact with the MME identified by the mapped 5G GUTI to retrieve the UE context. The AMF shall include the enclosed TAU request or ATTACH request in the Context Request message to the MME. The MME shall verify the TAU request or ATTACH request using the stored UE security context and if the verification is successful, the MME shall send the UE context to the AMF.The AMF shall verify the integrity of the Registration Request message if the AMF obtained the 5G security context identified by the 5G GUTI. In case the verification succeeds then the AMF shall then dispose of any EPS security parameters received from the source MME in the Context Response message. In case the verification fails or the 5G UE context is not available then the AMF shall treat the Registration Request message as if it was unprotected. In such case, the AMF may either derive a mapped 5G security context from the EPS context received from the source MME as described in clause 8.6.2 or initiate a primary authentication procedure to create a new native 5G security context. If triggered by home network, the AMF performs the primary authentication as described in clause 6.1.5.If the AMF derives a mapped 5G security context from the EPS security context, then the ngKSI associated with the newly derived mapped 5G security context and the uplink and downlink 5G NAS COUNTs are defined and set as described in clause 8.6.2. If the Registration Request contains a TAU Request or ATTACH request message, the network shall use the uplink EPS NAS COUNT corresponding to the TAU Request or ATTACH request message for deriving the KAMF'from the KASME. The AMF shall use and include the ngKSI to the UE in NAS SMC procedure, for the UE to identify the EPS security context used for the derivation of a mapped 5G security context. If a mapped 5G security context is created or the native 5G security context has been changed (e.g., due to a new KAMF'derivation or NAS algorithm change) , the AMF shall activate the resulting 5G security context by a NAS SMC procedure. When a mapped 5G security context is created, the AMF shall store the selected EPS NAS security algorithms in the mapped 5G security context and include them in the NAS Security Mode Command.If the AMF wants to continue to use the native 5G security context used by the UE to protect the Registration Request, the AMF may skip the NAS SMC procedure and send the Registration Accept message protected using the native 5G security context identified by the 5G-GUTI and the ngKSI included in the Registration Request message.In case the type value in the received ngKSI in NAS SMC indicates a mapped security context, then the UE shall use the value field in the received ngKSI to identify the EPS security context from which the UE derives the mapped 5G security context as described in clause 8.6.2. The UE shall activate the mapped 5G security context to verify the integrity protection of the NAS SMC as it is performed for a 5G NAS message over a 3GPP access.The Registration Accept message shall be protected by the new mapped 5G security context (if a mapped 5G security context was activated by NAS SMC) or by the new native 5G security context (if a new native 5G security context was activated by NAS SMC) as it is performed for a 5G NAS message over a 3GPP access. Otherwise, the current native 5G security context shall be used. If the AMF chooses to derive an initial KgNB from a new KAMF key (either the mapped KAMF'key or the native KAMF key) , then the initial KgNB is derived as specified in Annex A. 9 using the start value of the uplink 5G NAS COUNT protecting the NAS Security Mode Command Complete message and an access type distinguisher set to "3GPP access". If the UE receives an AS SMC message, then the UE shall derive an initial KgNB from a new KAMF key in the same way as the AMF.Various implementations of the disclosed technology provide techniques for a security algorithm selection in the handover from EPS to 5GS. The proposed implementations can prevent issues caused by the inconsistent length of supporting cryptographic algorithms of the EPS and 5GS. In the description below, it is assumed that both the AMF and gNB / ng-eNB support 256-bit security algorithms.In some implementations, in order to solve the algorithm selection problem in the handover procedure, the AMF can send request message forwarded by MME to UE to ask for UE 5G security capabilities and select algorithms after receiving UE 5G security capabilities from UE. In some implementations, in order to solve the algorithm selection problem in the handover procedure, the AMF can provide information on 256-bit security algorithms supported by the AMF to UE and let UE perform algorithm selection. In some implementations, in order to solve the algorithm selection problem in the registration procedure, the AMF can compare the algorithms presented in its configured list and the UE 5G security capabilities. If both the AMF and the UE support 256-bit cryptographic algorithms, the AMF can select 256-bit NAS security algorithms based on its local policy by performing NAS SMC procedures. The various implementations of the disclosed technology will be described with reference to FIGS. 2-4 below.Embodiment 1If the target AMF does not receive the UE 5G security capabilities from the source MME during handover from EPS to 5GS, the AMF can send a request message forwarded by MME to UE to ask for UE 5G security capabilities. FIG. 2 illustrates an example of a handover process from EPS to 5GS based on Embodiment 1. The description below is provided to explain each operation as shown in FIG. 2.1. The source eNB sends a Handover Required message to the source MME, including UE's identity.2. The source MME selects the target AMF and sends a Forward Relocation Request to the selected target AMF. The source MME includes UE's EPS security context including KASME, eKSI, UE EPS security capabilities, selected EPS NAS algorithm identifiers, uplink and downlink EPS NAS COUNTs, {NH, NCC} pair, in this message. If the source MME has the UE NR security capabilities stored, then it will forward the UE NR security capabilities as well to the target AMF.3. The target AMF checks whether the UE 5G security capabilities is received.If the target AMF does not receive the UE 5G security capabilities from the source MME, then the AMF sends a request message to UE forwarding by source MME to ask for UE 5G security capabilities. The UE's identity should be included in the message.If the target AMF receives the UE 5G security capabilities from the source MME, then step 4-6 shall be skipped.4. The source MME forwards the request message to UE.5. Upon receiving the request, the UE shall provide its 5G security capabilities in the response message.6. The source MME forwards the response message to the target AMF.7. The target AMF shall construct a mapped 5G security context from the EPS security context received from the source MME. The target AMF shall derive a mapped KAMF'key from the received KASME and the NH value in the EPS security context received from the source MME. The target AMF shall select the 5G NAS security algorithms (to be used in the target AMF for encryption and integrity protection) which are in the UE 5G security capabilities and also have the highest priority from its configured list. If UE 5G security capabilities indicate that the UE supports 256-bit algorithms, the target AMF can select 256-bit NAS security algorithms based on its local policy.The target AMF then derives the complete mapped 5G security context. The target AMF shall derive the 5G NAS keys (i.e., KNASenc and KNASint) from the new KAMF'with the selected 5G NAS security algorithm. The ngKSI for the newly derived KAMF'key is defined such as the value is taken from the eKSI of the KASME key (i.e. included in the received EPS security context) and the type is set to indicate a mapped security context. The target AMF shall store the EPS NAS security algorithms received from the source MME in the mapped 5G security context. The target AMF shall also set the NCC to zero and shall further derive the temporary KgNB using the mapped KAMF'key and the uplink NAS COUNT value of 232-1.The target AMF associates this mapped 5G Security context with ngKSI.The target AMF shall create a NAS Container to signal the necessary security parameters to the UE. The NAS Container shall include a NAS MAC, the selected 5G NAS security algorithms, the ngKSI associated with the derived KAMF'a nd the NCC value associated with the NH parameter used in the derivation of the KAMF'. The target AMF shall calculate the NAS MAC with the COUNT parameter set to the maximal value of 232-1.The target AMF shall increment the downlink NAS COUNT by one after creating a NAS Container.8. The target AMF requests the target gNB / ng-eNB to establish the bearer (s) by sending the Handover Request message.The target AMF sends the NAS Container created in step 7 along with the {NCC=0, NH=derived temporary KgNB} , the New Security Context Indicator (NSCI) , and the UE security capabilities in the Handover Request message to the target gNB / ng-eNB. The target AMF shall further set the NCC to one and shall further compute a NH. The target AMF shall further store the {NCC=1, NH} pair.9. The target gNB / ng-eNB shall select the 5G AS security algorithms from the list in the UE security capabilities. If the UE 5G security capabilities indicate that the UE supports 256-bit algorithms, the target gNB / ng-eNB can select 256-bit AS security algorithms based on its local policy.The target gNB / ng-eNB shall compute the KgNB to be used with the UE by performing the key derivation with the {NCC, NH} pair received in the Handover Request message and the target PCI and its frequency ARFCN-DL. The target gNB / ng-eNB shall associate the NCC value received from AMF with the KgNB. The target gNB  / ng-eNB shall then derive the 5G AS security context, by deriving the 5G AS keys (KRRCint, KRRCenc, KUPint, and KUPenc) from the KgNB and the selected 5G AS security algorithm identifiers.The target gNB / ng-eNB sends a Handover Request Ack message to the target AMF. Included in the Handover Request Ack message is the Target to Source Container, which contains the selected 5G AS algorithms, the keySetChangeIndicator, the NCC value from the received {NH, NCC} pair, and the NAS Container received from the target AMF. If the target gNB / ng-eNB had received the NSCI, it shall set the keySetChangeIndicator field to true, otherwise it shall set the keySetChangeIndicator field to false.10. The target AMF sends the Forward Relocation Response message to the source MME. The required security parameters obtained from gNB / ng-eNB in step 9 as the Target to Source Container are forwarded to the source MME.11. The source MME sends the Handover Command to the source eNB. The source eNB commands the UE to handover to the target 5G network by sending the Handover Command. This message includes all the security related parameters in the NAS Container obtained from the target AMF in step 10.12. The UE derives a mapped KAMF'key from the KASME in the same way the AMF did in step 7. It shall also derive the 5G NAS keys and KgNB corresponding to the AMF and the target gNB / ng-eNB in step 7 and step 9. The UE shall further set the selected EPS NAS security algorithms in the 5G security context to the NAS security algorithms used with the source MME. It associates this mapped 5G security context with the ngKSI included in the NAS Container. The UE shall verify the NAS MAC in the NAS Container.If verification of the NAS MAC fails, the UE shall abort the handover procedure. Furthermore, the UE shall discard the new NAS security context if it was derived and continue to use the existing NAS and AS security contexts.The mapped 5G security context shall become the current 5G security context.13. The UE sends the Handover Complete message to the target gNB / ng-eNB. This shall be ciphered and integrity protected by the AS keys in the current 5G security context.14. The target gNB / ng-eNB notifies the target AMF with a Handover Notify message.Embodiment 2-1FIG. 3 illustrates an example of a handover process from EPS to 5GS based on Embodiment 2-1. The description below is provided to explain each operation as shown in FIG. 3.1. The source eNB sends a Handover Required message to the source MME, including UE's identity.2. The source MME selects the target AMF and sends a Forward Relocation Request to the selected target AMF. The source MME includes UE's EPS security context including KASME, eKSI, UE EPS security capabilities, selected EPS NAS algorithm identifiers, uplink and downlink EPS NAS COUNTs, {NH, NCC} pair, in this message. If the source MME has the UE NR security capabilities stored, then it will forward the UE NR security capabilities as well to the target AMF.3. The target AMF shall construct a mapped 5G security context from the EPS security context received from the source MME. The target AMF shall derive a mapped KAMF'key from the received KASME and the NH value in the EPS security context received from the source MME.If the target AMF receives the UE 5G security capabilities, then the target AMF shall select the 5G NAS security algorithms (to be used in the target AMF for encryption and integrity protection) which have the highest priority from its configured list.If the target AMF does not receive the UE 5G security capabilities from the source MME, then shall set the UE 5G security capabilities in the mapped 5G NAS security context according to this default set:a. NEA0, 128-NEA1 and 128-NEA2 for NAS signalling ciphering, RRC signalling ciphering and UP ciphering;b. 128-NIA1 and 128-NIA2 for NAS signalling integrity protection, RRC signalling integrity protection and UP integrity protection.The target AMF shall not select any NAS security algorithms. Instead, the target AMF shall select several supported algorithms including both 128-bit algorithms and 256-bit algorithms and offer the algorithm list for UE to select. Specifically, the AMF can select one ciphering algorithm from NEA0, 128-NEA1, 128-NEA2, one 128-bit integrity algorithm from 128-NIA1 and 128-NIA2, and all the supported 256-bit algorithms. Then the AMF derives the 5G NAS keys (i.e., KNASenc and KNASint) according to each algorithm respectively.The target AMF shall create a NAS Container to signal the necessary security parameters to the UE. If the AMF has selected 5G NAS security algorithms, the NAS Container shall include a NAS MAC, the selected 5G NAS security algorithms, the ngKSI associated with the derived KAMF'a nd the NCC value associated with the NH parameter used in the derivation of the KAMF'. If the AMF has provided a supported algorithm list, the NAS Container shall include the NAS MACs calculated with different keys derived from different algorithms, the supported 5G NAS security algorithms corresponding to each NAS MAC listing in the same order, e.g., (NAS MAC1, NAS MAC2, NAS MAC3, . . ., Algorithm1, Algorithm 2, Algorithm3, . . . ) . The ngKSI associated with the derived KAMF'a nd the NCC value associated with the NH parameter used in the derivation of the KAMF's hould also be included in the NAS Container.The target AMF shall increment the downlink NAS COUNT by one after creating a NAS Container.4. The target AMF requests the target gNB / ng-eNB to establish the bearer (s) by sending the Handover Request message.The target AMF sends the NAS Container created in step 3 along with, the {NCC=0, NH=derived temporary KgNB} , the New Security Context Indicator (NSCI) in the Handover Request message to the target gNB / ng-eNB. The UE security capabilities should be included in the message if received from source MME. Otherwise, the default set of UE 5G security capabilities needs to be included. The target AMF shall further set the NCC to one and shall further compute a NH as specified in Annex A. 10. The target AMF shall further store the {NCC=1, NH} pair.5. The target gNB / ng-eNB shall selects the 5G AS security algorithms from the list in the UE security capabilities.The target gNB / ng-eNB shall compute the KgNB to be used with the UE by performing the key derivation with the {NCC, NH} pair received in the Handover Request message and the target PCI and its frequency ARFCN-DL. The target gNB / ng-eNB shall associate the NCC value received from AMF with the KgNB. The target gNB  / ng-eNB shall then derive the 5G AS security context, by deriving the 5G AS keys (KRRCint, KRRCenc, KUPint, and KUPenc) from the KgNB and the selected 5G AS security algorithm identifiers.The target gNB / ng-eNB sends a Handover Request Ack message to the target AMF. Included in the Handover Request Ack message is the Target to Source Container, which contains the selected 5G AS algorithms, the keySetChangeIndicator, the NCC value from the received {NH, NCC} pair, and the NAS Container received from the target AMF. If the target gNB / ng-eNB had received the NSCI, it shall set the keySetChangeIndicator field to true, otherwise it shall set the keySetChangeIndicator field to false.6. The target AMF sends the Forward Relocation Response message to the source MME. The required security parameters obtained from gNB / ng-eNB in step 5 as the Target to Source Container are forwarded to the source MME.7. The source MME sends the Handover Command to the source eNB. The source eNB commands the UE to handover to the target 5G network by sending the Handover Command. This message includes all the security related parameters in the NAS Container obtained from the target AMF in step 6.8. The UE derives a mapped KAMF'key from the KASME in the same way the AMF did in step 7. If the selected 5G NAS security algorithms are received in the NAS Container, the UE shall derive the 5G NAS keys and KgNB corresponding to the AMF and the target gNB / ng-eNB in step 3 and step 5. If the AMF supported algorithm list are received in the NAS Container, the UE shall compare the received algorithms with its security capabilities and select 256-bit algorithms as NAS security algorithms if it is both supported by UE and AMF. After the algorithm selection, the UE shall verify the NAS MAC corresponding to the selected integrity algorithm. If the verification succeeds, then the UE derives 5G NAS keys and KgNB with the NAS and AS algorithms, respectively.If verification of the NAS MAC fails, the UE shall abort the handover procedure. Furthermore, the UE shall discard the new NAS security context if it was derived and continue to use the existing NAS and AS security contexts.9. The UE sends the Handover Complete message to the target gNB / ng-eNB. This shall be ciphered and integrity protected by the AS keys in the current 5G security context.10. The target gNB / ng-eNB notifies the target AMF with a Handover Notify message.11. After the handover procedure is completed successfully, the UE performs mobility registration update. The UE sends the Registration Request message with registration type set to "Mobility Registration Update". The 5G security capabilities alongside the mapped 5G GUTI is included in the message. The selected NAS security algorithm should also included in the message if it is not selected by AMF before. The UE integrity protects the Registration Request using the selected security algorithms in the current 5G NAS security context.12. Upon receiving the request message, the AMF should set NAS security algorithms to the received ones if it is not decided before and derive 5G NAS keys. Then AMF verifies the integrity of the Registration Request message and complete normal registration procedure with UE.Embodiment 2-2In Embodiment 2-1, only 256-bit algorithms for NAS security are selected during the handover procedure. The 256-bit algorithms for AS security can be selected during mobility registration update procedure after the handover by adding Operation 13 (which is not shown in FIG. 3) after Operation 12 as discussed in Embodiment 2-1.13. The gNB / ng-eNB also compares the received UE 5G security capabilities with the ones in the current 5G AS security context. The UE 5G security capability is received from UE in the registration request in Step 11 of Embodiment 2-1. The registration request is sent from UE to gNB and then the gNB performs the AMF selection and forward the message to the AMF. Upon comparing of the received UE 5G security capabilities with the ones in the current 5G AS security context, if they are different, the gNB / ng-eNB shall update the current 5G AS security context with the received UE 5G security capabilities and re-select an AS security algorithm. If the UE 5G security capabilities indicate that the UE supports 256-bit algorithms, the gNB / ng-eNB can select 256-bit AS security algorithm according to its local policy. Then the gNB / ng-eNB and UE activate the resulting 5G AS security context by an AS SMC procedure.Embodiment 3Upon receiving the Registration Request following the handover procedure, the AMF needs to compare the algorithms presented in its configured list and in the UE 5G security capabilities. If both the AMF and the UE support 256-bit cryptographic algorithms, the AMF can select 256-bit NAS security algorithms based on its local policy by performing NAS SMC procedures. FIG. 4 illustrates an example of a registration process performed after a handover from EPS to 5GS based on Embodiment 3. The description below is provided to explain each operation as shown in FIG. 4. While FIG. 4 illustrates steps 0 to 8, some of the steps are omitted. For example, the steps 5, 6, and 8, which are illustrated in the dotted line in FIG. 4, are optional operations and can be omitted.0. The handover from EPS to 5GS over N26 is completed successfully. During the handover procedure, the AMF does not receive the UE 5G security capabilities from the source MME, so the AMF assumes that the following default set of 5G security algorithms are supported by the UE (and sets the UE 5G security capabilities in the mapped 5G NAS security context according to this default set) :a. NEA0, 128-NEA1 and 128-NEA2 for NAS signalling ciphering, RRC signalling ciphering and UP ciphering;b. 128-NIA1 and 128-NIA2 for NAS signalling integrity protection, RRC signalling integrity protection and UP integrity protection.Then, the 5G NAS and AS security algorithms are selected from the list.1. The UE sends the Registration Request message with registration type set to "Mobility Registration Update". The 5G security capabilities alongside the mapped 5G GUTI is included in the message. The UE integrity protects the Registration Request using the selected security algorithms in the current 5G NAS security context.2. The (R) AN selects an AMF.3. The (R) AN forwards the message to the selected AMF.4. The AMF verifies the integrity of the Registration Request message if the AMF obtained the 5G security context identified by the 5G GUTI. If the verification succeeds, the AMF shall skip Step 5.5. If the verification fails or the 5G UE context is not available, the AMF shall treat the Registration Request message as if it was unprotected. In such case, the AMF initiates a primary authentication procedure to create a new native 5G security context.6. The AMF compares the UE 5G security capabilities received in Registration Request with the ones in the current 5G security context. If they are different, the AMF shall update the current 5G security context with the received UE 5G security capabilities and re-select a NAS security algorithm. If the UE 5G security capabilities indicate that the UE supports 256-bit algorithms, the AMF can select 256-bit NAS security algorithm according to its local policy. Then the AMF activates the resulting 5G security context by a NAS SMC procedure.7. After the completed NAS SMC procedure, the AMF sends a Registration Accept message to the UE. The Registration Accept message shall be protected by the new mapped 5G security context (if a mapped 5G security context was activated by NAS SMC) or by the new native 5G security context (if a new native 5G security context was activated by NAS SMC) .8. The gNB / ng-eNB also compares the received UE 5G security capabilities with the ones in the current 5G AS security context. If they are different, the gNB / ng-eNB shall update the current 5G AS security context with the received UE 5G security capabilities and re-select an AS security algorithm. If the UE 5G security capabilities indicate that the UE supports 256-bit algorithms, the gNB / ng-eNB can select 256-bit AS security algorithm according to its local policy. Then the gNB / ng-eNB and UE activate the resulting 5G AS security context by an AS SMC procedure.FIG. 5 illustrates an example of a wireless communication system that includes a BS 520 (e.g., eNB) and a BS 530 (e.g., gNB) that are connected to EPC and 5GC, respectively. One or more user equipment (UE) 511 and 512 are in communication with the BS 520 and the BS 530. In some embodiments, the uplink transmissions (531, 532) can include uplink control information (UCI) , higher layer signaling (e.g., UE assistance information or UE capability) , or uplink information. In some embodiments, the downlink transmissions (541, 542) can include DCI or high layer signaling or downlink information. The UE may be, for example, a smartphone, a tablet, a mobile computer, a machine to machine (M2M) device, a terminal, a mobile device, an Internet of Things (IoT) device, and so on.FIG. 6 is a block diagram representation of a portion of an apparatus, in accordance with some embodiments of the presently disclosed technology. An apparatus 610 such as a network device or a base station or a wireless device (or UE) , can include processor electronics 620 such as a microprocessor that implements one or more of the techniques presented in this document. The apparatus 610 can include transceiver electronics 630 to send and / or receive wireless signals over one or more communication interfaces such as antenna (s) 640. The apparatus 610 can include other communication interfaces for transmitting and receiving data. Apparatus 610 can include one or more memories (not explicitly shown) configured to store information such as data and / or instructions. In some implementations, the processor electronics 620 can include at least a portion of the transceiver electronics 630. In some embodiments, at least some of the disclosed techniques, modules or functions are implemented using the apparatus 605.Some preferred embodiments may include the following solutions.1. A method of a wireless communication (e.g., method 700 as shown in FIG. 7) , comprising: receiving 710, by a mobile management entity (MME) in a first network from a base station in the first network, a first message indicating an initiation of a handover operation for a user device from the first network to a second network; receiving 720, by the MME from an access and mobility management function (AMF) in the second network, a second message requesting security capability information of the user device for the second network; sending 730, by the MME to the user device, a third message requesting the security capability information of the user device for the second network; receiving 740, by the MME from the user device, a response message including the security capability information of the user device for the second network; and sending 750, by the MME to the AMF, the security capability information of the user device for the second network.2. The method of solution 1, wherein the second message includes identification information of the user device.3. A method of a wireless communication (e.g., method 800 as shown in FIG. 8) , comprising: receiving 810, by an access and mobility management function (AMF) from a mobile management entity (MME) in a first network, a request for relocating a user device from the first network to a second network; sending 820, by the AMF to the MME, a message requesting security capability information of the user device for the second network; and receiving 830, by the AMF from the MME, the security capability information of the user device for the second network.4. The method of solution 3, further comprising, after the receiving of the request and before the sending of the message: checking, by the AMF, whether the AMF has received the security capability information of the user device for the second network.5. The method of solution 3, wherein the message includes identification information of the user device.6. The method of solution 3, further comprising, after the receiving of the security capability information, selecting a security algorithm for the second network based on the security capability information, wherein the security algorithm corresponds to a 256-bit security algorithm in a case that the security capability information indicates that the user device supports 256-bit algorithms.7. The method of solution 3, further comprising: sending, by the AMF to a network node in the second network, a handover request message, the handover request message causing a base station in the second network to select a 256-bit security algorithm for the second network in a case that the security capability information indicates that the user device supports 256-bit algorithms.8. A method of a wireless communication (e.g., method 900 as shown in FIG. 9) , comprising: receiving 910, by a user device from a mobile management entity (MME) in a first network, a message requesting security capability information of the user device for a second network; and sending 920, by the user device to the MME, a response message including the security capability information of the user device for the second network.9. The method of solution 8, wherein the message includes security related parameters and the method further comprising: generating, by the user device, a security context based on the security related parameters.10. A method of a wireless communication (e.g., method 1000 as shown in FIG. 10) , comprising: receiving 1010, by an access and mobility management function (AMF) in a second network from a mobile management entity (MME) in a first network, a first message requesting for relocating a user device from the first network to the second network, the first message including a first security context for the first network; generating 1020, by the AMF, a second security context for the second network corresponding to the first security context for the first network, the second security context being generated with or without selecting a security algorithm for the second network based on whether the first message including a security capability information of the user device for the second network; and sending 1030, by the AMF to a gNB in the second network, a second message requesting a handover and including a selected security algorithm or security parameters calculated based on candidate algorithms.11. The method of solution 10, further comprising, after the receiving of the first message and before the generating of the second security context for the second network: checking, by the AMF, whether the AMF has received the security capability information of the user device for the second network.12. The method of solution 10, wherein, in a case that the first message omits the security capability information for the second network, the generating of the second security context includes setting a security capability information in the second security context based on a default set.13. The method of solution 12, wherein the default set includes: i) NEA0, 128-NEA1 and 128-NEA2; or ii) 128-NIA1 and 128-NIA2.14. The method of solution 10, wherein, in a case that the first message omits the security capability information for the second network, the generating of the second security context includes: generating an algorithm list for the user device, the algorithm list including the candidate algorithms including at least one 128-bit algorithm and at least one 256-bit algorithm.15. The method of solution 14, wherein the algorithm list includes candidate algorithms including all of 256-bit algorithms supported by the AMF.16. The method of solution 14, wherein the at least one 128-bit algorithm in the algorithm list includes one ciphering algorithm from NEA0, 128-NEA1, 128-NEA2, one 128-bit integrity algorithm from 128-NIA1 and 128-NIA2.17. The method of solution 14, further comprising: creating a container to be sent to the user device, the container including MACs calculated with different keys derived from different candidate algorithms.18. The method of solution 10, further comprising: receiving, by the AMF from the user device, a registration request including a 256-bit algorithm that has been selected for the second network; and setting, by the AMF, the security algorithm as received.19. A method of a wireless communication (e.g., method 1100 as shown in FIG. 11) , comprising: receiving 1110, by a user device from a network node in a first network, a handover command to perform a handover from the first network to a second network, the handover command including security parameters; checking 1120 whether the handover command includes a security algorithm selected for the second network or a candidate security algorithm for the second network, the security algorithm being configured to protect signaling messages; comparing 1130, in response to the checking indicates that the handover command includes the candidate security algorithm for the second network algorithms, the candidate security algorithm with security capability information of the user device; and selecting 1140 a 256-bit algorithm to be used for the second network based on a result of the comparing that indicates the 256-bit algorithm is supported by the user device and an access and mobility management function (AMF) .20. The method of solution 19, further comprising, after the selecting of the 256-bit algorithm: performing, by the user device, a verification process of a MAC corresponding to the 256-bit algorithm; and deriving a security key for the second network based on the 256-bit algorithm.21. The method of solution 19, further comprising, sending, by the user device to the AMF, a registration request including the 256-bit algorithm selected for the second network.22. A method of a wireless communication (e.g., method 1200 as shown in FIG. 12) , comprising: receiving 1210, by a network node in a second network from an access and mobility management function (AMF) in a first network, a handover request from the first network to the second network, the handover request including 1) security capability information of a user device for the second network in a case that the security capability information of the user device has been provided to the AMF from a mobile management entity (MME) or 2) a container including MACs calculated with different keys derived from different candidate algorithms included in an algorithm list for the user device in a case that the security capability information has not been provided to the AMF from the MME; and receiving 1220, by the network node from the user device, a handover complete message.23. The method of solution 22, wherein the algorithm list includes candidate algorithms including at least one 128-bit algorithm and at least one 256-bit algorithm, the candidate algorithms configured to protect signaling messages, and wherein, during a handover procedure, a 256-bit algorithm is selected by the user device in a case that the 256-bit algorithm is supported by the user device and the AMF.24. The method of solution 22, wherein the algorithm list includes candidate algorithms including all of 256-bit algorithms supported by the AMF.25. The method of solution 22, further comprising: receiving security capability information of the user device for the second network; comparing a received security capability information with security capabilities in a current security context configured to protect user plane data; updating the current security context with the received security capability information in a case that a result of the comparing indicates that the received security capability information is different from the security capabilities in the current security context; and selecting a security algorithm for protecting the user plane data.26. The method of solution 25, wherein a 256-bit security algorithm is selected as the security algorithm in a case that the received security capability information indicates that the user device supports the 256-bit security algorithm.27. The method of solution 25, further comprising: performing, by the network node in the second network, an SMC (Security Mode Control) procedure to activate an updated security context.28. A method of a wireless communication (e.g., method 1300 as shown in FIG. 13) , comprising: receiving 1310, by an AMF from a user device, a registration request including security capability information of the user device, the registration request received after completing a handover from a first network to a second network; comparing 1320 the security capability information of the user device with security capabilities in a current security context; updating 1330 the current security context with the security capability information included in the registration request in a case that a result of the comparing indicates that the security capability information is different from the security capabilities in the current security context; and selecting 1340 a security algorithm for protecting signaling messages.29. The method of solution 28, wherein a 256-bit security algorithm is selected as the security algorithm in a case that the security capability information indicates that the user device supports the 256-bit security algorithm.30. The method of solution 28, further comprising: performing, by the AMF, an SMC (Security Mode Control) procedure to activate an updated security context.31. A method of a wireless communication (e.g., method 1400 as shown in FIG. 14) , comprising: sending 1410, by a user device to an AMF, a registration request including security capability information of the user device, the registration request sent after completing a handover from a first network to a second network; performing 1420 a first SMC procedure that activates a first security context updated by the AMF based on the security capability information included in the registration request; and performing 1430 a second SMC procedure that activates a second security context updated by a network node in the second network based on the security capability information included in the registration request.32. The method of solution 31, wherein the first security context and the second security context correspond to NAS (Non-Access-stratum) security context and AS (Access-stratum) security context, respectively.33. A method of a wireless communication (e.g., method 1500 as shown in FIG. 15) , comprising: receiving 1510, by a network node in a second network from a user device, a registration request including security capability information of the user device, the registration request received after completing a handover from a first network to the second network; comparing 1520 the security capability information of the user device with security capabilities in a current security context; updating 1530 the current security context with the security capability information included in the registration request in a case that a result of the comparing indicates that the security capability information is different from the security capabilities in the current security context; and selecting 1540 a security algorithm for protecting signaling messages.34. The method of solution 33, wherein a 256-bit security algorithm is selected as the security algorithm in a case that the security capability information indicates that the user device supports the 256-bit security algorithm.35. The method of solution 33, further comprising: performing, by the network node in the second network, an SMC (Security Mode Control) procedure to activate an updated security context.36. A wireless communication apparatus comprising a processor configured to implement a method recited in any of above solutions.37. A computer storage medium having code stored thereupon, the code, upon execution by a processor, causing the processor to implement a method recited in any of above solutions.The disclosed and other embodiments, modules and the functional operations described in this document can be implemented in digital electronic circuitry, or in computer software, firmware, or hardware, including the structures disclosed in this document and their structural equivalents, or in combinations of one or more of them. The disclosed and other embodiments can be implemented as one or more computer program products, i.e., one or more modules of computer program instructions encoded on a computer readable medium for execution by, or to control the operation of, data processing apparatus. The computer readable medium can be a machine-readable storage device, a machine-readable storage substrate, a memory device, a composition of matter effecting a machine-readable propagated signal, or a combination of one or more them. The term "data processing apparatus"encompasses all apparatus, devices, and machines for processing data, including by way of example a programmable processor, a computer, or multiple processors or computers. The apparatus can include, in addition to hardware, code that creates an execution environment for the computer program in question, e.g., code that constitutes processor firmware, a protocol stack, a database management system, an operating system, or a combination of one or more of them. A propagated signal is an artificially generated signal, e.g., a machine-generated electrical, optical, or electromagnetic signal, that is generated to encode information for transmission to suitable receiver apparatus.A computer program (also known as a program, software, software application, script, or code) can be written in any form of programming language, including compiled or interpreted languages, and it can be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program does not necessarily correspond to a file in a file system. A program can be stored in a portion of a file that holds other programs or data (e.g., one or more scripts stored in a markup language document) , in a single file dedicated to the program in question, or in multiple coordinated files (e.g., files that store one or more modules, sub programs, or portions of code) . A computer program can be deployed to be executed on one computer or on multiple computers that are located at one site or distributed across multiple sites and interconnected by a communication network.The processes and logic flows described in this document can be performed by one or more programmable processors executing one or more computer programs to perform functions by operating on input data and generating output. The processes and logic flows can also be performed by, and apparatus can also be implemented as, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application specific integrated circuit) .Processors suitable for the execution of a computer program include, by way of example, both general and special purpose microprocessors, and any one or more processors of any kind of digital computer. Generally, a processor will receive instructions and data from a read only memory or a random access memory or both. The essential elements of a computer are a processor for performing instructions and one or more memory devices for storing instructions and data. Generally, a computer will also include, or be operatively coupled to receive data from or transfer data to, or both, one or more mass storage devices for storing data, e.g., magnetic, magneto optical disks, or optical disks. However, a computer need not have such devices. Computer readable media suitable for storing computer program instructions and data include all forms of non-volatile memory, media and memory devices, including by way of example semiconductor memory devices, e.g., EPROM, EEPROM, and flash memory devices; magnetic disks, e.g., internal hard disks or removable disks; magneto optical disks; and CD ROM and DVD-ROM disks. The processor and the memory can be supplemented by, or incorporated in, special purpose logic circuitry.While this document contains many specifics, these should not be construed as limitations on the scope of an invention that is claimed or of what may be claimed, but rather as descriptions of features specific to particular embodiments. Certain features that are described in this document in the context of separate embodiments can also be implemented in combination in a single embodiment. Conversely, various features that are described in the context of a single embodiment can also be implemented in multiple embodiments separately or in any suitable sub-combination. Moreover, although features may be described above as acting in certain combinations and even initially claimed as such, one or more features from a claimed combination can in some cases be excised from the combination, and the claimed combination may be directed to a sub-combination or a variation of a sub-combination. Similarly, while operations are depicted in the drawings in a particular order, this should not be understood as requiring that such operations be performed in the particular order shown or in sequential order, or that all illustrated operations be performed, to achieve desirable results.Only a few examples and implementations are disclosed. Variations, modifications, and enhancements to the described examples and implementations and other implementations can be made based on what is disclosed.

Claims

1.A method of a wireless communication, comprising:receiving, by a mobile management entity (MME) in a first network from a base station in the first network, a first message indicating an initiation of a handover operation for a user device from the first network to a second network;receiving, by the MME from an access and mobility management function (AMF) in the second network, a second message requesting security capability information of the user device for the second network;sending, by the MME to the user device, a third message requesting the security capability information of the user device for the second network;receiving, by the MME from the user device, a response message including the security capability information of the user device for the second network; andsending, by the MME to the AMF, the security capability information of the user device for the second network.2.The method of claim 1,wherein the second message includes identification information of the user device.3.A method of a wireless communication, comprising:receiving, by an access and mobility management function (AMF) from a mobile management entity (MME) in a first network, a request for relocating a user device from the first network to a second network;sending, by the AMF to the MME, a message requesting security capability information of the user device for the second network; andreceiving, by the AMF from the MME, the security capability information of the user device for the second network.4.The method of claim 3, further comprising, after the receiving of the request and before the sending of the message:checking, by the AMF, whether the AMF has received the security capability information of the user device for the second network.5.The method of claim 3, wherein the message includes identification information of the user device.6.The method of claim 3, further comprising, after the receiving of the security capability information,selecting a security algorithm for the second network based on the security capability information,wherein the security algorithm corresponds to a 256-bit security algorithm in a case that the security capability information indicates that the user device supports 256-bit algorithms.7.The method of claim 3, further comprising:sending, by the AMF to a network node in the second network, a handover request message, the handover request message causing a base station in the second network to select a 256-bit security algorithm for the second network in a case that the security capability information indicates that the user device supports 256-bit algorithms.8.A method of a wireless communication, comprising:receiving, by a user device from a mobile management entity (MME) in a first network, a message requesting security capability information of the user device for a second network;sending, by the user device to the MME, a response message including the security capability information of the user device for the second network.9.The method of claim 8, wherein the message includes security related parameters and the method further comprising:generating, by the user device, a security context based on the security related parameters.10.A method of a wireless communication, comprising:receiving, by an access and mobility management function (AMF) in a second network from a mobile management entity (MME) in a first network, a first message requesting for relocating a user device from the first network to the second network, the first message including a first security context for the first network;generating, by the AMF, a second security context for the second network corresponding to the first security context for the first network, the second security context being generated with or without selecting a security algorithm for the second network based on whether the first message including a security capability information of the user device for the second network; andsending, by the AMF to a gNB in the second network, a second message requesting a handover and including a selected security algorithm or security parameters calculated based on candidate algorithms.11.The method of claim 10, further comprising, after the receiving of the first message and before the generating of the second security context for the second network:checking, by the AMF, whether the AMF has received the security capability information of the user device for the second network.12.The method of claim 10,wherein, in a case that the first message omits the security capability information for the second network, the generating of the second security context includes setting a security capability information in the second security context based on a default set.13.The method of claim 12, wherein the default set includes:i) NEA0, 128-NEA1 and 128-NEA2; orii) 128-NIA1 and 128-NIA2.14.The method of claim 10,wherein, in a case that the first message omits the security capability information for the second network, the generating of the second security context includes:generating an algorithm list for the user device, the algorithm list including the candidate algorithms including at least one 128-bit algorithm and at least one 256-bit algorithm.15.The method of claim 14, wherein the algorithm list includes candidate algorithms including all of 256-bit algorithms supported by the AMF.16.The method of claim 14, wherein the at least one 128-bit algorithm in the algorithm list includes one ciphering algorithm from NEA0, 128-NEA1, 128-NEA2, one 128-bit integrity algorithm from 128-NIA1 and 128-NIA2.17.The method of claim 14, further comprising:creating a container to be sent to the user device, the container including MACs calculated with different keys derived from different candidate algorithms.18.The method of claim 10, further comprising:receiving, by the AMF from the user device, a registration request including a 256-bit algorithm that has been selected for the second network; andsetting, by the AMF, the security algorithm as received.19.A method of a wireless communication, comprising:receiving, by a user device from a network node in a first network,a handover command to perform a handover from the first network to a second network, the handover command including security parameters;checking whether the handover command includes a security algorithm selected for the second network or a candidate security algorithm for the second network, the security algorithm being configured to protect signaling messages;comparing, in response to the checking indicates that the handover command includes the candidate security algorithm for the second network algorithms, the candidate security algorithm with security capability information of the user device; andselecting a 256-bit algorithm to be used for the second network based on a result of the comparing that indicates the 256-bit algorithm is supported by the user device and an access and mobility management function (AMF) .20.The method of claim 19, further comprising, after the selecting of the 256-bit algorithm:performing, by the user device, a verification process of a MAC corresponding to the 256-bit algorithm; andderiving a security key for the second network based on the 256-bit algorithm.21.The method of claim 19, further comprising,sending, by the user device to the AMF, a registration request including the 256-bit algorithm selected for the second network.22.A method of a wireless communication, comprising:receiving, by a network node in a second network from an access and mobility management function (AMF) in a first network, a handover request from the first network to the second network, the handover request including 1) security capability information of a user device for the second network in a case that the security capability information of the user device has been provided to the AMF from a mobile management entity (MME) or 2) a container including MACs calculated with different keys derived from different candidate algorithms included in an algorithm list for the user device in a case that the security capability information has not been provided to the AMF from the MME; andreceiving, by the network node from the user device, a handover complete message.23.The method of claim 22,wherein the algorithm list includes candidate algorithms including at least one 128-bit algorithm and at least one 256-bit algorithm, the candidate algorithms configured to protect signaling messages, andwherein, during a handover procedure, a 256-bit algorithm is selected by the user device in a case that the 256-bit algorithm is supported by the user device and the AMF.24.The method of claim 22, wherein the algorithm list includes candidate algorithms including all of 256-bit algorithms supported by the AMF.25.The method of claim 22, further comprising:receiving security capability information of the user device for the second network;comparing a received security capability information with security capabilities in a current security context configured to protect user plane data;updating the current security context with the received security capability information in a case that a result of the comparing indicates that the received security capability information is different from the security capabilities in the current security context; andselecting a security algorithm for protecting the user plane data.26.The method of claim 25, wherein a 256-bit security algorithm is selected as the security algorithm in a case that the received security capability information indicates that the user device supports the 256-bit security algorithm.27.The method of claim 25, further comprising:performing, by the network node in the second network, an SMC (Security Mode Control) procedure to activate an updated security context.28.A method of a wireless communication, comprising:receiving, by an AMF from a user device, a registration request including security capability information of the user device, the registration request received after completing a handover from a first network to a second network;comparing the security capability information of the user device with security capabilities in a current security context;updating the current security context with the security capability information included in the registration request in a case that a result of the comparing indicates that the security capability information is different from the security capabilities in the current security context; andselecting a security algorithm for protecting signaling messages.29.The method of claim 28, wherein a 256-bit security algorithm is selected as the security algorithm in a case that the security capability information indicates that the user device supports the 256-bit security algorithm.30.The method of claim 28, further comprising:performing, by the AMF, an SMC (Security Mode Control) procedure to activate an updated security context.31.A method of a wireless communication, comprising:sending, by a user device to an AMF, a registration request including security capability information of the user device, the registration request sent after completing a handover from a first network to a second network;performing a first SMC procedure that activates a first security context updated by the AMF based on the security capability information included in the registration request; andperforming a second SMC procedure that activates a second security context updated by a network node in the second network based on the security capability information included in the registration request.32.The method of claim 31, wherein the first security context and the second security context correspond to NAS (Non-Access-stratum) security context and AS (Access-stratum) security context, respectively.33.A method of a wireless communication, comprising:receiving, by a network node in a second network from a user device, a registration request including security capability information of the user device, the registration request received after completing a handover from a first network to the second network;comparing the security capability information of the user device with security capabilities in a current security context;updating the current security context with the security capability information included in the registration request in a case that a result of the comparing indicates that the security capability information is different from the security capabilities in the current security context; andselecting a security algorithm for protecting signaling messages.34.The method of claim 33, wherein a 256-bit security algorithm is selected as the security algorithm in a case that the security capability information indicates that the user device supports the 256-bit security algorithm.35.The method of claim 33, further comprising:performing, by the network node in the second network, an SMC (Security Mode Control) procedure to activate an updated security context.36.A wireless communication apparatus comprising a processor configured to implement a method recited in any of above claims.37.A computer storage medium having code stored thereupon, the code, upon execution by a processor, causing the processor to implement a method recited in any of above claims.

Citation Information

Patent Citations

  • Switching method and terminal equipment

    CN110913393A

  • Communication method and related equipment

    CN112153647A

  • Management of user equipment security capabilities in communication system

    CN113424506A

  • Security capability negotiation method, system, and equipment

    US20180070275A1